Local Denial of Service Vulnerability in grep by GNU
CVE-2015-1345
Currently unrated
Summary
The bmexec_trans function in kwset.c of grep versions 2.19 through 2.21 is susceptible to a local denial of service attack. By providing crafted input when using the -F option, local users can trigger an out-of-bounds heap read, leading to a crash of the application. This vulnerability poses a risk of service disruption for systems relying on these versions of grep.
References
Timeline
Vulnerability published
Vulnerability Reserved